[July 2026 Release] Real-time Guardrails for Claude Cowork, Kiro CLI, Human-in-the-Loop Overrides & More. Learn more->

[July 2026 Release] Real-time Guardrails for Claude Cowork, Kiro CLI, Human-in-the-Loop Overrides & More. Learn more->

[July 2026 Release] Real-time Guardrails for Claude Cowork, Kiro CLI, Human-in-the-Loop Overrides & More. Learn more->

Akto Extends Real-time DLP to Claude via Inference Hooks

Akto now integrates with Anthropic's inference hooks to inspect and block Claude Enterprise prompts before the model processes them. Server-side enforcement across Claude.ai, Cowork, Code, and Design.

Krishanu

Krishanu

Akto's Integration with Claude's Compliance API
Akto's Integration with Claude's Compliance API

Earlier this year, Akto launched its Claude Compliance Connector, giving security teams visibility into Claude Enterprise activity and continuous compliance monitoring. That integration answered a critical first question for enterprises adopting Claude at scale:

What is happening inside our AI environment, and is it compliant?

The next question is harder, but just as important:

Can we stop sensitive data from reaching the model in the first place?

Akto already enforces in real time through a browser extension and endpoint shield on the desktop, CLI, and IDE. These catch prompts when they happen. But they depend on something being installed on the employee's device. If the extension is missing or the endpoint agent is not deployed, coverage has a gap.

Akto is now expanding its enforcement methods through a native integration with Anthropic's inference hooks protocol, inspecting prompts and tool call data before they reach inference. Inference hooks run on Anthropic's infrastructure, not on the device. One configuration covers Claude.ai, Claude Cowork, Claude Code, and Claude Design. Managed laptops, unmanaged laptops, it does not matter. If the prompt goes to Claude Enterprise, it goes through Akto first.

The browser extension and endpoint shield continue to operate as before. Inference hooks add a third enforcement layer with nothing new to deploy on the endpoint.

How It Works

When an employee submits a prompt on any Claude Enterprise surface, Anthropic sends the full conversation transcript as a signed HTTPS POST to Akto's endpoint before Claude processes anything. Akto validates the webhook signature, inspects the transcript against your configured guardrail policies, and returns a verdict: allow or deny.

An allowed prompt proceeds to Claude normally. A denied prompt never reaches the model. The employee sees a clear explanation of which policy was violated, plus any standing guidance your administrators configured (who to contact, how to request an exception). The event is logged in your Akto dashboard with full context: the policy that triggered, the user, the Claude surface, and a timestamp. Denials also appear in your organization's compliance Activity Feed in Claude Enterprise.

One configuration covers everything. You set it once at the organization level, and it applies across web, desktop, and CLI sessions, including tool call responses from MCP connectors, skills, and plugins.

Anthropic signs every request using the Standard Webhooks specification, so Akto can cryptographically verify each payload came from Anthropic. If Akto is unreachable or times out, your organization's failure handling setting decides the outcome: block the request by default, or allow it through uninspected. Your call.

Why Prompt-Time Inspection Matters

The Compliance Connector tells you what happened. Useful for audits, investigations, and reporting. But by the time you see a violation, the model has already processed the data.

Once sensitive information enters an LLM's inference layer, traditional deletion and redaction do not apply the way they do for a file in storage. A single prompt containing customer PII, unreleased financial data, or proprietary source code creates a risk that is difficult to reverse.

Inference hooks move the control point in front of the model. If your policy says a prompt carrying patient health records should not reach Claude, it does not reach Claude. The data stays where it was. The Compliance Connector gives you the record. Inference hooks give you the gate.

What Gets Evaluated at the Gate

Data leakage prevention. PII, credentials, API keys, financial data, health records, and proprietary information in prompts are detected before they reach the model. Whether an employee pastes a customer list into Claude.ai or a developer includes production database credentials in a Claude Code session, Akto catches it at the hook.

Prompt injection and jailbreak detection. Prompts containing encoded commands, indirect injection patterns (via tool results or attached documents), or attempts to override system instructions are flagged and blocked. This matters especially for Claude Cowork and Claude Code, where the agent executes multi-step workflows with tool access.

Custom organizational policy enforcement. Define policies specific to your business: restrict prompts referencing M&A activity, block discussions of internal projects outside approved user groups, prevent prompts that reference production infrastructure in non-engineering contexts.

Tool call inspection. When Claude calls a tool through an MCP connector, skill, or plugin, the tool's response routes through the inference hook before it reaches the model. Akto inspects those responses for sensitive data or policy violations, so data pulled from your internal systems does not get processed by Claude without a policy check.

Full Coverage Across Managed and Unmanaged Devices

With inference hooks, Akto now provides three enforcement methods for Claude Enterprise, all reporting to the same dashboard:

Browser extension for the browser.

Endpoint shield for the desktop, CLI, and IDE.

Inference hooks on Anthropic's infrastructure, covering every Claude Enterprise surface with no client-side deployment. They reach unmanaged devices, BYOD laptops, and any session where the browser extension or endpoint agent is not present.

Each layer catches what the others cannot. Together, they give you one place to see every Claude interaction across your organization, every verdict, every blocked prompt, every policy violation.

Deploy Without Disrupting Your Workforce

Anthropic built graduated enforcement into the protocol. Shadow mode lets Akto receive and evaluate prompts without blocking anything, so your team can review verdicts and tune policies before enforcement goes live. Percentage-based rollout inspects a configurable fraction of requests. Role-based exclusions exempt specific groups entirely.

Start in shadow mode. Watch the verdicts. Adjust your policies. Move to enforcement when you are ready.

Follow us for more updates

Experience enterprise-grade Agentic Security solution